autofeat docs
Reference

CLI

Every autofeat command, with the flags the binary actually accepts.

Install the package and run autofeat. autofeat --version and autofeat -V print the version and exit. With no subcommand, the CLI prints help.

Commands below are the ones registered on the Typer app. Flags not listed here are not part of that command.

autofeat route

Route one GitHub webhook JSON file to a Decision. Exit 0 even when dispatch is false. Needs the network to read the journal unless --no-remote-state is set.

autofeat route --event ./event.json --event-name pull_request --explain
autofeat route --event ./event.json --output ./decision.json --no-remote-state
FlagMeaning
--eventRequired. Webhook payload JSON.
--event-namepull_request, issue_comment, or workflow_dispatch.
--configPath to .autofeat/config.yml. Default: that file under the working directory.
--outputWrite Decision JSON here. Default: stdout.
--explainPrint every guard as PASS, FAIL, or SKIPPED.
--no-remote-stateDo not read the journal or sticky. Treat state as absent.

autofeat exec

Execute a Decision and write <run-dir>/result.json. Exit 1 when result.ok is false or a blocking budget alert fired. A spend alert alone warns.

autofeat exec --decision ./decision.json --repo-dir .
FlagMeaning
--decisionRequired. Decision JSON from route or simulate.
--repo-dirCheckout. Default .
--run-dirArtifact directory. Default <repo>/.autofeat/run.
--configIgnored. Policy comes from the decision snapshot, not this path.

autofeat simulate

Same router as route, with no network and no GitHub writes. Use it to iterate on a fixture.

autofeat simulate --event ./event.json --state ./run-state.json --explain
FlagMeaning
--eventRequired. Webhook payload JSON.
--configConfig path. Default: .autofeat/config.yml under the working directory.
--stateRunState JSON. Default: no prior state.
--explainPrint every guard as PASS, FAIL, or SKIPPED.
--event-nameEvent name. Inferred from the payload when omitted.

autofeat init

Actions path only. Writes .github/workflows/autofeat.yml and .autofeat/config.yml, creates labels, and runs doctor. See Actions path.

FlagMeaning
--repo-dirCheckout. Default .
--forceOverwrite existing workflow or config.
--releaselatest or vX.Y.Z. Default latest.

autofeat doctor

Preflight for the Actions path. Exit 1 if any row is FAIL. --repo-dir defaults to .. --json prints JSON instead of a table.

A banner is printed above the rows, not as a row:

EFFECTIVE POLICY: merge_mode=stop_before_merge dry_run=true

When dry_run is false and merge_mode is auto, the banner adds: WARNING: dry_run=false with merge_mode=auto permits unattended merges.

Row order:

RowWhat it checks
config.autofeat/config.yml loads.
workflow.github/workflows/autofeat.yml exists and its uses: pin is a SHA or a version tag. Missing file is FAIL.
app_credentialsAUTOFEAT_APP_ID and AUTOFEAT_APP_PRIVATE_KEY are set.
signing_keyAUTOFEAT_SIGNING_KEY when signatures are required.
app_tokenInstallation token can list repositories.
labelsThe four labels exist.
merge_targetThe configured base branch exists.
auto_approveBranch protection versus auto_approve. See below.
state_rulesetRuleset autofeat-state-refs is active and has no bypass actors. Missing, or not visible to the token, is WARN when dry_run is true and FAIL otherwise. Bypass actors the token cannot see are WARN.
budget_alertPASS when alert_usd <= budget.usd. The schema already rejects a larger alert, so a loaded config passes this row.
budget_estimatePASS with budget.usd, alert_usd, and the note costs are estimated from token counts.
policy_modePASS, or WARN when mode is full and dry_run is false.
allowed_actionsThe derived or configured action list.
policy_reviewerReviewer provider and model. Null means no override.
agent_uidPASS when the agent UID is separate. WARN when allow_same_uid is true.

auto_approve row: false is PASS. True with an unknown approval count is WARN (could not read branch protection). True with a required approval count above 0 is WARN. True with zero required approvals is PASS. The hint when approvals are required: the App cannot approve a pull request it authored.

On a hosted repository that correctly has no workflow, workflow FAILs and app_credentials FAILs. That is the Actions-path preflight, not a sign that the App install is broken.

autofeat setup-app

Create a private GitHub App for the Actions path, or verify an existing one. This is not how you install the hosted App autofeat-axc.

FlagMeaning
--nameNew App name.
--repoowner/name that receives secrets.
--forceOverwrite.
--timeoutSeconds. Default 600.
--verify-appApp id to verify. Does not create an App and does not write secrets.
--key-pathPEM for --verify-app.

Exit 2 means installation or repository access was not verified.

autofeat hosted

Serve the receiver. --check prints the hosted config JSON and exits. No other flags.

autofeat worker

Pull Pub/Sub and run one container per job. No flags.

autofeat hosted-run

Container entrypoint: verify, check out, supervise. No flags.

autofeat directive

render

Print a markdown directive. --sign HMACs it with AUTOFEAT_SIGNING_KEY.

FlagMeaning
--actionRequired. plan, implement, test, review, gate, merge, or halt.
--methodOptional. Default is the action's default method.
--turnInteger. Default 0.
--body-fileMarkdown body. Default empty.
--signSign with AUTOFEAT_SIGNING_KEY.
--repoBinding owner/name.
--prBinding pull request number.
--head-shaBinding head SHA.

parse

autofeat directive parse --file ./comment.md. Prints JSON. A file that is not a directive prints not a directive and exits 0.

verify

autofeat directive verify --file ./comment.md. Exit 0 when the HMAC is valid, exit 1 when it is not. The reason goes to stderr. Uses AUTOFEAT_SIGNING_KEY.

autofeat reconcile

Operator only. Use this when the journal ref is missing or GitHub cut the commit message. A repository owner cannot repair that from a label. See Troubleshooting.

prepare

Print a signed reconciliation request. Redirect it to a file and read it before apply.

autofeat reconcile prepare \
  --repo owner/repo \
  --pr 123 \
  --usd 1.5 \
  --tokens 100000 \
  --minutes 12 \
  --reason "ledger rebuilt from check-run annotations"
FlagMeaning
--repoRequired. owner/name.
--prRequired. Pull request number, at least 1.
--usdRequired. Confirmed cumulative USD, at least 0.
--tokensRequired. Confirmed cumulative tokens, at least 0.
--minutesRequired. Confirmed cumulative minutes, at least 0.
--reasonRequired. Why this correction is right.
--correct-measuredLower an over-charged measured ledger. Each total must be <= the current total.
--adopt-truncatedAdopt the signed sticky when GitHub cut the journal message at 65536 characters. Totals stay as restated.
--operatorRequired together with --correct-measured or --adopt-truncated.

--correct-measured and --adopt-truncated cannot be combined.

apply

autofeat reconcile apply --repo owner/repo --pr 123 --file ./request.md

Verifies the signed request, writes the corrected totals, and records the audit. --file must exist and be readable.

On this page